google-nomulus/docs/operational-procedures
jianglai c426a80563 Add a new reservation type to support nameserver restrictions
A new field (allowedNameservers) is added to ReservedListEntry that stores the allow nameservers for the label. The field itself is a comma separated string, but the actual lines within a reserved list file (from which the field is parsed) uses colon to separate nameservers, to avoid conflicting with the commas used as primary separators in a CSV file.

Combined with upcoming update(s) that enables locking down an entire TLD to only delegate domains with a nameserver restricted reservation type, this change will enable us to restrict domain delegation to nameservers specifically specified in the allowed nameservers list, in order to prevent malicious delegation in case the registrar for a brand TLD is compromised.

-------------
Created by MOE: https://github.com/google/moe
MOE_MIGRATED_REVID=149989330
2017-03-21 14:56:31 -04:00
..
brda-deposits.md Post-submit changes to BRDA and RDE documentation 2016-10-14 17:49:14 -04:00
premium-list-management.md Don't allow duplicates in premium/reserved lists 2017-02-27 11:17:58 -05:00
rde-deposits.md Update documentation about manually creating RDE commands 2017-01-18 11:05:06 -05:00
reserved-list-management.md Add a new reservation type to support nameserver restrictions 2017-03-21 14:56:31 -04:00